Mobile Application
Penetration Testing

Test your iOS or Android app and its supporting APIs. We check stored data, network traffic, permissions, and authentication.

Overview

The app in their pocket is in scope too.

We test iOS and Android apps against the OWASP Mobile Application Security Verification Standard, combining static and dynamic analysis with runtime instrumentation, and always test the client and its backend APIs together. Free retest within 60 days.


Coverage

What we test.

Client-side and server-side coverage aligned to OWASP MASVS and MSTG.

  • Insecure local data storage
  • Network communication & TLS
  • Certificate pinning bypass
  • Authentication & session handling
  • Binary protections & anti-tampering
  • Reverse engineering & hooking
  • Hardcoded secrets & keys
  • Backend API security
Methodologies: OWASP MASVS OWASP MSTG Static & dynamic analysis CVSS v3.1

FAQ

Mobile penetration testing FAQ

Scope, cost, and what happens next.

How much does a mobile application penetration test cost?
Typically €3,000–6,000 for a single platform including its backend, with both platforms scoped together for more. Use our estimator for a tailored figure.
How long does a mobile penetration test take?
Most take 5 to 10 working days of active testing plus reporting, depending on platform coverage and backend complexity.
Do you test both iOS and Android?
Yes — including React Native and Flutter apps. We can scope a single platform or both together.
Do you test the backend API as well?
Yes — we always assess the app with its backend APIs, since most serious mobile risk lives in server-side authorisation and data handling.
What do we receive after the test?
A CVSS-scored technical report with reproduction steps, an executive summary, an attestation letter, and a free retest within 60 days.
What do you need to start a mobile test?
The app builds (IPA/APK or TestFlight/Play access), test accounts for each role, and backend/API details. We confirm scope and quote from there.
More questions about this service
Do you test on real devices?
Yes — we use a mix of real devices and emulators, including jailbroken/rooted environments for deeper analysis.
Do you cover React Native and Flutter apps?
Yes — alongside native iOS and Android, we test cross-platform frameworks including React Native and Flutter.
Is our source code required?
No — mobile tests are typically grey/black-box, but providing source enables deeper white-box coverage if you want it.
Do you check app-store and platform requirements?
We focus on security, but findings often overlap with platform guidance; we flag anything likely to affect store review.

Ready to test your mobile app?

Tell us what you’re working on. We’ll help you work out the next step.

Book a short call Send an email